Amendments to the Claims 



1 . (original) A method of establishing a consistent password policy, 
said method comprising: 

describing a plurality of password policies in a computer usable password 
policy data structure; 

accessing said computer usable password policy data structure by a 
password policy enforcement agent; and 

enforcing at least one of said plurality of password policies described 
within said password policy data structure by said password policy enforcement 
agent. 

2. (currently amended) The method of Claim 1 wherein said computer 
usable password policy data structure comprises a file structure substantially 
compatible with extensible markup language. 

3. (original) The method of Claim 1 wherein said password policy 
enforcement agent is operable on a client computer of a client-server computer 
system. 

4. (currently amended) The method of Claim 1 wherein said method 
is_operable on a utility data center. 
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5. (original) The method of Claim 1 further comprising validating said 
computer usable password policy data structure for authenticity by said password 
policy enforcement agent. 

6. (original) The method of Claim 1 wherein said plurality of password 
policies comprises a threshold parameter for unsuccessful access attempts that 
when exceeded disables a computer system access account. 

7. (currently amended) The method of Claim 6 wherein said plurality 
of password policies comprises a parameter indicating the-a time duration , and 
wherein exceeding said threshold parameter w i th i n wh i ch sa i d throcho ld 
param e t o r numbor of unsucc o ssfu l acc o ss attempts t riggers locking of a 
computer system access account within said time duration . 

8. (original) The method of Claim 1 wherein said plurality of password 
policies comprises an initial delay parameter to block access to a computer 
system access account for a period of time after an unsuccessful access attempt. 

9. (currently amended) The method of Claim 8 wherein access to 
said computer system access account is delayed for an increasing time period 
for successive unsuccessful access attempts. 
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10. (original) The method of Claim 1 wherein said plurality of password 
policies comprises a minimum password length parameter. 

1 1 . (original) The method of Claim 1 wherein said plurality of password 
policies comprises a maximum password length parameter. 

12. (currently amended) The method of Claim 1 wherein said plurality 
of password policies comprises a_paramete r to proh i b i t passwords cons i sting of a 
natural languago word for prohibiting passwords comprising a word associated 
with a natural language . 

1 3. (currently amended) The method of Claim 12_[[1 ]]wherein said 
natural language is English. 

14. (currently amended) The method of Claim 1 wherein said plurality 
of password policies comprises a parameter for prohibiting to prohib i t passwords 
comprising consist i ng of a palindrome. 

15. (currently amended) The method of Claim 1 wherein said plurality 
of password policies comprises a parameter for prohibiting to prohibit passwords 
comprising consist i ng of a derivative of a computer system account name. 
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16. (currently amended) The method of Claim 1 wherein said plurality 
of password policies comprises a parameter for te-automatically generating 
genorato a password. 

1 7. (currently amended) The method of Claim 1_[[1 6 ]]wherein said 
plurality of password policies comprises a_parameter for to-automatically 
generating g e n e rate a pronounceable password consistent with a ll of said 
plurality of password policies. 

1 8. (currently amended) The method of Claim 1_[[1 6 ]]wherein said 
plurality of password policies comprises a_parameter for specifying to spec i fy a 
set of characters utilizable to automatically generate a password. 

19. (currently amended) The method of Claim 1 further comprising 
providing, by said password policy enforcement agent, feedback to a 
configuration and aggregation point, about whether said at least one of said 
plurality of password policies wh i ch of sa i d plurality of paeswofd pnlir.i n r . h .n vn 
has been successfully enforced. 

20. (currently amended) A comput e r usab lo password policy data 
structur o compris i ng comput e r access p a ssword po l icy param o t o rs. 
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Instructions on a computer usable medium wherein the instructions when 
executed cause a computer system to perform a method of establishing a 
consistent password policy, said method comprising: 

describing a plurality of password policies in a computer usable password 
policy data structure: 

providing an access point with access to said computer usable password 
policy data structure: and 

receiving feedback from a password policy enforcement agent associated 
with said a ccess point about which of said plurality of password policies have 
been successfully enforced. 

21. (currently amended) The computer usable medium of Claim 20 
wherein said computer usable password policy data structure of Claim 20 
compris i ng comprises a file structure substant i a ll y compatible with extensible 
markup language. 

22. (currently amended) The computor uoablo password po li cy data 
structure of Claim 20 comprising a computor accoss password po li cy paramotor 
se l octod from th o s o t of comput e r a cc o ss password policy parameters 
comprising computer usable medium of Claim 20 wherein said method further 
comprises : 

selecting a com puter access password policy parameter from said plurality 
of computer access p assword policy parameters consisting of a parameter 
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selected fro m a group of parameters comprising a threshold parameter for 
unsuccessful access attempts that when exceeded disables a computer system 
access account[[;]L_a parameter indicating the a time duration within which said 
threshold parameter number of unsuccessful access attempts triggers locking of 
a computer system access account[[;]]ian initial delay parameter to block access 
to a computer system access account for a period of time after an unsuccessful 
access attempt[[;]L_a minimum password length parameter[[;]La maximum 
password length parameter[[;]La parameter to prohibit passwords consisting of a 
natural language word[[;]La parameter to prohibit passwords consisting of a 
palindrome[[;]La parameter to prohibit passwords consisting of a derivative of a 
computer system account name[[;]La parameter to automatically generate a 
password[[;]L_a parameter to automatically generate a pronounceable password 
consistent with all of said plurality of password policies[[;]Land a parameter to 
specify a set of characters utilizable to automatically generate a password. 

23. (currently amended) A computer system comprising: 

a computer usable password policy data structure comprising a plurality of 
password policies; and 

a server configured to provide access to said computer usable password 
policy data structure at an access point configured to enforce at least one of said 
plurality of password policies using a password policy enforcement agent. 

a f i rst sorvor computor for contro ll ing accocs to caid computor oyctom; 
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a s o cond sorvor computer coup l ed to caid f i rst server computor for 

providing contro l of said comput e r syst e m; 

comput o r us a b l o m o dia comprising computor usab l o i nstructions th a n 

wh e n e x e cut e d on a procossor of sa i d f i rst sorv o r computor i mp l omont a m e thod 
of e stab li sh i ng a cons i st e nt password pol i cy, sa i d m e thod compr i s i ng: 

accessing a computor usab l o password policy dat a structur e ; and 

e nforc i ng a password po li cy doscr i bod w i th i n sa i d password po li cy data 

struoturo. 

24. (original) The computer system of Claim 23 comprising a utility 
data center. 
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